Your Data Rights
Last updated: August 2, 2026
On this page
Our privacy policy states in plain terms what we collect. This page does a different job: who controls it, which rights apply to you and where, and exactly how to make a request. Read the privacy policy first if you just want the plain-English version; read this one for controller identity and rights mechanics.
Your rights, and where they apply
We process a short, specific list of personal data, itemised in full in "What personal data we actually hold" below and in plainer language on our privacy policy. Depending on where you are, a different law may give you rights over that data: GDPR if you're in the EU, India's Digital Personal Data Protection Act if you're in India, and simply having asked, if neither applies to you.
Whichever applies to you, the process is the same: email us and we'll respond within thirty days. You don't need to name a law or prove which regime covers you. "Your rights, and how to use them" below has the full list of what you can ask for.
We haven't decided whether GDPR formally applies to this site, and we're not pretending otherwise here. "Why we are allowed to hold it" covers the lawful-basis reasoning under each regime, and "What changes if this applies to us" covers what we'll do if that changes. None of that affects your ability to ask us something today; that works regardless.
Who controls your data
IndexMesh is the data controller for whatever personal data this website holds, described in full below. The company is IndexMesh Private Limited, incorporated in India (CIN U62013KL2026PTC105133), registered office 43/1574, Suite No 037, Kochappilly Road, Palarivattom, Ernakulam, Kerala - 682025, India.
What personal data we actually hold
Website visitors: aggregate request counts, not linked to you as an individual. We use Cloudflare Web Analytics, a short cookieless script served from Cloudflare's own domain, which counts page visits without setting cookies, without following you across other websites, and without building a profile of you. Requests are also recorded in our host's standard server logs, which include IP addresses, separately from this script.
People who use a notify form: your email address, which form you used and which page you were on, held on a Brevo list from the moment you confirm by clicking the link in our email, until you unsubscribe or ask us to delete it.
People who use the contact form: your name, your email address, the subject you choose if you choose one, your message, and the page you sent it from. The form relays your message once, through Brevo, to our own inbox, so we can reply and keep a record of the conversation. It does not add you to any list. If you email us directly instead, we hold your address and what you write, in Google Workspace.
Anyone who submits either form: a short-lived, salted hash of your IP address, kept only long enough to limit spam (up to an hour for notify, up to a day for contact) and never linked to what you typed.
WordPress plugin users: nothing, by design. The plugin is built to run inside your own site rather than send us any data.
That is the complete list. We operate no customer database, no CRM beyond the notify lists described above, and no advertising profiles.
Why we are allowed to hold it
GDPR and India's DPDP Act ask this question differently, so here are two separate answers for the little data described above.
Under GDPR: server logs and cookieless analytics rest on our legitimate interest in running a secure website and understanding which pages are useful, which we consider low-impact because the data is not used to identify or profile you. The short-lived IP hash kept for spam limiting rests on the same legitimate interest in keeping these forms usable. A notify-form address rests on your consent. Email correspondence, including anything sent through the contact form, rests on your having chosen to contact us, which we treat as both consent and our legitimate interest in being able to reply.
Under DPDP: the Act does not have GDPR's open-ended legitimate-interest basis. Section 4 permits consent, or one of the specific uses enumerated in section 7. A notify-form address is held on consent, exactly as under GDPR. Email correspondence you choose to send us is voluntarily provided for a specified purpose, which section 7 recognises. Server logs, cookieless analytics and the anti-spam IP hash are security-related processing; whether a specific section 7 clause covers them, or whether they need a separate consent basis, is a question for qualified counsel and is not asserted here.
Your rights, and how to use them
We want EU and Indian visitors, and anyone else who asks, to know what these rights look like, and to know they can ask us regardless of where they are. You can ask us what personal data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict how we use it, ask for a copy in portable form, or object to our processing it. Under the DPDP Act you can also nominate someone to exercise these rights on your behalf.
Email hello@indexmesh.ai. We will respond within thirty days. You do not need to explain why you are asking, and we will not treat you differently for having asked.
In practice, unless you have emailed us before, the honest answer to a request will usually be that we hold nothing about you beyond undifferentiated server logs.
Where your data goes
This site runs on Cloudflare Pages, a US company with a globally distributed edge network, so requests are served, and logs generated, at whichever location picks them up. Brevo, our vendor for the notify and contact forms, hosts its databases in the EU. A contact-form relay or a direct email also reaches Google Workspace, the mailbox it lands in. We're an Indian company with account-level access to that Brevo database from India. We're still filling in subprocessor and support-access facts for each vendor in our internal register. We treat the EU as its own transfer regime, and we haven't put a transfer safeguard like Standard Contractual Clauses in place, because none is needed yet. If that changes, we'll put one in place first and say so here.
We keep a notify-form address on its Brevo list until you unsubscribe or ask us to delete it, and email correspondence for as long as the conversation is useful before deleting it. Brevo keeps a delivery log of each contact-form relay, showing the recipient, subject and time but not the message text, for 12 months and then deletes it automatically. The IP hash used for spam limiting is deleted automatically within a day at most. We set no retention period on aggregate analytics because they are not linked to individuals.
What changes if this applies to us
We are not GDPR certified, and we never will claim to be: no such generic certification exists for a company to hold. The only recognised EU scheme (Europrivacy) is a narrow, paid, audited certification for specific named processing operations, not a badge a company can self-declare. What we can honestly commit to instead is what changes the moment our footprint does:
If we ever confirm that IndexMesh for WordPress processes data on behalf of an EU-based site owner, in a way that makes us a processor of that owner's own visitors' data, we will offer that owner a data processing agreement before they need to ask for one.
If personal data ever needs to flow from the EU to us in India in a way that requires a transfer safeguard, we will put one in place, such as the Standard Contractual Clauses, and say so here. We do not represent one as already in effect today, because it is not.
We will review this page each time either trigger occurs, rather than leave a stale non-applicability position in place after the facts have moved on.
If you are not satisfied
Email us first and we will try to put it right. If you are in the EU you can complain to your national data protection authority. If you are in India you can complain to the Data Protection Board.
See also: Privacy and Cookie policy.
Common questions
Does the WordPress plugin send my data to IndexMesh?
No. It is designed to run entirely inside your own WordPress installation and, by design, does not send data to IndexMesh or to any third party. We do not receive anything from it, which means there is no plugin data for a rights request to reach.
Do I need a data processing agreement to use the plugin?
No, because the plugin is designed not to process any data on your behalf: it operates only within your own site. If that ever changes, for example if we confirm the plugin processes data for an EU site owner, we will publish a DPA and say so clearly rather than wait to be asked.
Are you GDPR compliant, or GDPR certified, as an Indian company?
No generic "GDPR compliant" or "GDPR certified" status exists for a company to hold or claim, so we don't use either label. The only recognised EU scheme, Europrivacy, is a narrow, paid, audited certification for specific named processing operations, not a badge to self-declare. What we can tell you honestly is what we process, which rights apply to you, and how to exercise them — see "Your rights, and where they apply" above and "Your rights, and how to use them" below. Email us if you need a definitive answer about your own situation.
If I fill in a notify form, am I subscribed right away?
No. Submitting the form sends you a confirmation email and adds nothing anywhere. Only clicking the link in that email adds your address to the list, and that click is your consent record. Unsubscribing removes you and Brevo does not let us reinstate an unsubscribed or blocklisted address.
